menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Malware News

>

AMSI Patch...
source image

Medium

1w

read

175

img
dot

Image Credit: Medium

AMSI Patching Evasion

  • AMSI is Microsoft's security feature that scans and blocks suspicious PowerShell scripts.
  • A new technique patches AMSI functions in memory to make the scanner return an error code and allow code execution.
  • The tool locates the PowerShell process, calculates the memory addresses of critical AMSI functions, and writes a small assembly code patch to bypass scanning.
  • This technique disables AMSI's scanning capability directly at its source and allows PowerShell code execution without triggering security alerts.

Read Full Article

like

10 Likes

For uninterrupted reading, download the app